Android Malware Operations Merge Droppers, SMS Theft, and RAT Capabilities at Scale
In mobile assaults against consumers in Uzbekistan, threat actors have been seen using malicious dropper apps that pose as trustworthy apps to deliver an Android SMS stealer known as Wonderland.
According to a research released last week by Group-IB, users used to receive "pure" Trojan APKs that functioned as malware as soon as they were installed. These days, more and more enemies use droppers that pose as trustworthy apps. Although the dropper appears innocuous at first glance, it has a malicious payload that is installed locally even in the absence of an active internet connection.
The Singapore-based cybersecurity firm claims that Wonderland (previously WretchedCat) enables bidirectional command-and-control (C2) communication to carry out commands in real-time, enabling arbitrar...

